Log entries reference version 16.0.00000 after upgrade to 25.1 - Data Loss Prevention
search cancel

Log entries reference version 16.0.00000 after upgrade to 25.1 - Data Loss Prevention

book

Article ID: 448273

calendar_today

Updated On:

Products

Data Loss Prevention

Issue/Introduction

 After upgrading to Data Loss Prevention (DLP) 25.1, log entries in the Enforce Server or Endpoint Prevent Server continue to reference the 16.0 version directory for incidentblobdata or compatibility thresholds. This occurs even when the system is otherwise functional on version 25.1.

Symptoms The SymantecDLPDetector.log or IncidentPersister.log contains entries similar to:

Source: com.vontu.util.config.SystemProperties.setSystemProperties Message: System Properties: com.symantec.dlp.incident.blob.externalization.dir=####/ProgramData/Symantec/DataLossPrevention/EnforceServer/16.0.00000/incidentblobdata

The MonitorController.properties file may also contain:

com.vontu.monitor.controller.endpointsystemevent.checkCompatibility.warningAgents.threshold = 16.0.00000

 

 

Environment

  • Symantec Data Loss Prevention 25.1
  • Upgraded from version 16.0 MP1

Cause

During the upgrade process, certain configuration files retain the hardcoded paths or version thresholds from the previous installation.

Resolution

Update the configuration files to reference the correct 25.1 paths:

  1. Navigate to the Enforce or Detection Server configuration directory:
    • Windows: C:\Program Files\Symantec\DataLossPrevention\EnforceServer\25.1\Protect\config\ (or equivalent path for Detection).
  2. Open Protect.properties in a text editor.
  3. Locate the following line: com.symantec.dlp.incident.blob.externalization.dir = ####/ProgramData/Symantec/DataLossPrevention/EnforceServer/16.0.00000/incidentblobdata
  4. Update the path to reflect the 25.1 directory structure.
  5. Restart the Symantec DLP Manager or Detection Server service for changes to take effect.

Additional Information

Please note:

If externalization is not being used the hard coded path is irrelevant.

If externalization is being used, we recommend you create a directory outside of the installation folder, preferably on a seperate drive with plenty of space.

For further assistance with log retrieval, see How to collect logs for Data Loss Prevention. To speak with a support engineer, see Contact Support.